Operation Arid Viper was designed to steal information from infected systems using a malware client capable of filtering out uninteresting files. The malware client was observed in traffic to be obfuscated with a standard-encoding. The campaign was targeting specific industry verticals: telecoms, high tech, and business services, primarily in Israel. Instead of a pornographic video, the actors showed a change in TTP by using as lure a video of a fiery automobile accident. The Trojan continues to download an update following the first C2 communication, and in this case researchers succeeded in patching the initial malware to obtain the second stage malware payload.”]
Source: https://informationsecuritybuzz.com/articles/operation-arid-viper-slithers-back-into-view/